SQL Injection Vulnerability in Featured Image from URL Plugin for WordPress
CVE-2025-10036
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 September 2025
What is CVE-2025-10036?
The Featured Image from URL plugin for WordPress is vulnerable to SQL Injection through the get_all_urls() function in all versions up to 5.2.7. This vulnerability arises due to inadequate escaping of user-supplied parameters and a lack of proper preparation in the SQL queries. Authenticated attackers with Administrator-level access can exploit this weakness to inject additional SQL commands into existing queries, potentially allowing them to retrieve sensitive information from the database. Users of this plugin should take immediate action to secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Featured Image from URL (FIFU) * <= 5.2.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved